AI DOERS
Book a Call
← All insightsAI Excellence

Claude Mythos: The Model Anthropic Says It Will Not Release

Anthropic confirmed Claude Mythos, a model above Opus that found over a hundred Firefox exploits where the prior model found two and cracked decades-old bugs. Because that power is so strong, Anthropic says it will not release it widely, and that has real consequences for your own systems.

Claude Mythos: The Model Anthropic Says It Will Not Release
Illustration: AI DOERS Studio

When Anthropic confirmed the existence of Claude Mythos, a frontier model the company is choosing not to release widely, most of the commentary focused on what the model can do. A model that found over a hundred Firefox exploits where the prior version found two is genuinely striking. A model that identified a twenty-seven-year-old vulnerability in a widely deployed operating system, one that had survived years of expert human security review, and a sixteen-year-old flaw in a media library embedded in billions of devices is not a minor capability increment. But the capability numbers are not the most important part of this story for business owners who depend on shared software infrastructure. The most important part is what the word emergent means and why it changes the calculus for what happens next.

I am Madhuranjan Kumar, and I want to take the Mythos situation apart from that angle: not what the model can do in isolation, but what this moment signals about the timeline and the decisions that business owners and the people who govern these technologies should be making right now.

Emergent capability is the most important concept in the Mythos story

Anthropic's official description of Mythos's security capability includes a specific and important detail: the ability to find software exploits was not trained into the model. It emerged from raw capability at the frontier level. The model was not specifically optimized for vulnerability research. The capability appeared as a byproduct of reaching a new level of general capability.

This distinction matters enormously. A trained capability can be scoped, limited, and audited in advance. You know what the model was trained to do, and you can design the deployment around that known scope. An emergent capability, by definition, was not anticipated before it appeared. You do not know what else is emerging alongside it. You do not have a pre-built framework for evaluating it. The decision about how to handle it comes after the fact, while the capability already exists.

This is what makes the Mythos disclosure different from an announcement of a new model that has been specifically optimized for a new task. Anthropic did not decide to train Mythos to find software vulnerabilities and then discover it was very good at that. They trained a frontier model to be more generally capable and discovered that this level of general capability includes the ability to find software vulnerabilities at a rate that no previous model and no small team of human researchers could match. The security capability was a side effect.

The implication for future releases is significant. If emergent capabilities appear at the frontier level without being specifically trained, then the evaluation process for any new frontier model has to include capability discovery that goes well beyond the benchmarks the model was designed to be tested against. Every new frontier model is potentially a new emergent capability that no one has yet identified. That reality is part of why Anthropic has made the decision they made, and why the governance question around that decision is more complicated than it first appears.

How it works (short)

The 100-exploit gap between Opus and Mythos reveals a threshold, not a gradient

On the Firefox browser specifically, Anthropic's prior frontier model found two working exploits during security testing. Mythos found over a hundred. Across major software systems it reportedly identified thousands of previously unknown, high-severity vulnerabilities. That is not an improvement in degree. It is a change in kind.

The difference between two exploits and a hundred in the same evaluation window is not a fifty-fold improvement in the same capability. It is the difference between a model that can find the occasional vulnerability when prompted in the right way and a model that systematically exhausts the exploitable attack surface of a complex application. Those are different capabilities at a structural level, not different points on the same curve.

This matters for how you think about security timelines. A gradual improvement in exploit-finding capability gives defenders time to adapt. A threshold crossing does not. If the capability moves from two to a hundred between one model generation and the next, the assumption that the security landscape changes slowly enough to track and respond to does not hold. The relevant question is not "is this capability getting better?" It is "has it crossed the threshold where it changes what a motivated adversary can do in a fixed amount of time?"

Mythos has clearly crossed that threshold. The question that matters for business owners and operators is when a similar capability becomes available outside the controlled research context Anthropic is currently managing. That brings the timeline discussion into focus.

SWE-bench performance at 93.9 percent, combined with the token efficiency improvements Anthropic describes, also signals that the gap between frontier and publicly available is larger than the public perception of AI capability currently reflects. Most users of AI tools form their expectations based on what they can access. The Mythos disclosure is a correction of that expectation: the capability frontier is further ahead of the access frontier than the available models suggest.

Known software flaws closed per month after a basic patch-and-cleanup routine

The work doesn't stop when one vendor holds back; it reroutes

Anthropic's decision not to release Mythos publicly is a meaningful act of restraint. Announcing a model and simultaneously announcing that you will not release it is a new precedent in the AI industry, and the fact that it came from the company that has most consistently prioritized safety framing in its public communications does not make it a simple decision. A model that generates revenue when deployed represents a concrete opportunity cost that Anthropic is choosing to accept.

But the restraint of one vendor does not stop the broader capability development. It reroutes it.

Project Glasswing, the coalition Anthropic launched alongside the Mythos disclosure with approximately twelve large technology partners including Google, Apple, and Nvidia, is the structured version of that rerouting. The explicit goal is to use Mythos-level capability to find and patch critical vulnerabilities in widely deployed software before a similar capability becomes available more broadly. Find the holes, close them, reduce the attack surface before the exploit-finding capability is no longer restricted to a controlled coalition.

OpenAI and xAI are notably absent from the coalition. That absence adds a competitive dimension to what is nominally a safety initiative. Whether those companies are absent because they were not invited, because they declined, or because they are pursuing parallel approaches through their own model programs is not publicly clear. What is clear is that the coalition's coverage of the software ecosystem is incomplete without them, and that the competitive dynamics of frontier AI development mean the incentive to withhold similar capabilities is likely to be weaker for companies whose business models depend more heavily on rapid deployment.

The open-source research trajectory adds a second rerouting path. Open-source models have historically followed the capability frontier of proprietary models at a lag of roughly six to twelve months. If that lag holds for the capabilities Mythos demonstrates, a similar level of exploit-finding capability could reach open-source models within a year of the Mythos disclosure. That is the timeline that gives the Glasswing coalition its urgency, and it is the timeline that makes the current moment actionable rather than theoretical for every business owner running software that has not been aggressively maintained.

The six-to-twelve month open-source lag is the actionable window for every business

The six-to-twelve month lag before frontier capabilities reach open-source approximations is not a guarantee. It is a historical pattern that has held reasonably consistently across several generations of model capability. It could be shorter. It could be longer. What it provides is a planning window: a period during which the most sophisticated exploit-finding capability is still concentrated in a small number of controlled deployments, and during which the highest-value defensive actions have the most time to take effect before the capability is more broadly distributed.

For most small and mid-sized businesses, the practical actions in that window are straightforward and do not require technical expertise. An electrical contractor running a scheduling application, a quoting tool, an email account holding customer home addresses and site access details, a cloud storage account with years of job photos, and a payment processing integration has a concrete defensive checklist that an afternoon of focused work can substantially complete.

The first action is automatic updates across every device and application the business uses. The majority of real-world security incidents exploit vulnerabilities for which a patch already existed at the time of the incident. Turning on automatic updates for the operating system, the applications, and the browsers on every device in the business closes the known vulnerability class without requiring any specialized knowledge. For the electrical contractor, this means checking the update settings on every tablet and laptop used in the field, the office scheduling computer, and any devices used for payment processing.

The second action is data minimization. Old customer records, years of job photos with home addresses visible in metadata or captions, email threads containing gate codes and alarm system details, and any stored financial information that is no longer needed for an active client relationship should be deleted rather than retained indefinitely. Data that does not exist cannot be exfiltrated. A business that has accumulated five years of customer files without a deletion policy has a much larger exposure in a security incident than one that retains only what is needed for active relationships. For the electrical contractor, a focused session deleting completed jobs older than two years that are no longer needed for warranty or reference purposes meaningfully reduces the potential impact of any future incident. The time cost is one afternoon. The cost of an incident involving years of customer home addresses and access details is a week of recovery at minimum and several thousand dollars in the best case, not counting reputational damage with clients who trusted the business with sensitive information about their homes.

The third action is two-factor authentication on the accounts where it matters most: the primary email account, which serves as the recovery key for almost every other account in the business, and any account tied to payments or payroll. Two-factor authentication stops the majority of account takeover attempts even when a password has been compromised, because the attacker needs the second factor in addition to the credential. For most small business accounts, enabling this takes ten to twenty minutes per account and adds a minor step to the login process that most people adapt to within a week.

Those three actions together represent one afternoon of focused work for a typical small business. The electrical contractor who completes all three before the open-source lag closes has substantially reduced the most common attack vectors without requiring any specialized security knowledge or any ongoing cost beyond the minor inconvenience of the authentication step.

The CRM and website stack the business uses to manage client relationships and the Google Ads campaigns it runs to generate new leads both touch customer data. Making sure those platforms are updated, that access credentials use two-factor authentication, and that the data stored in them reflects a minimization policy rather than indefinite accumulation is part of the same defensive posture.

Who decides is the question that matters more than what it can do

The governance question that Mythos forces is direct and currently unresolved. If a small group of people control a model that can systematically identify security vulnerabilities in almost any widely deployed software, the obvious question is who decides who gets access, for what purposes, and under what conditions.

Anthropic has made one set of decisions: no broad release, a controlled coalition with specific named partners for the specific purpose of closing vulnerabilities before the capability spreads. Those are reasonable decisions given the capability they are managing. But they are decisions made by a private company with its own commercial interests, its own research agenda, and its own assessment of risk and benefit. The framework they are using to make those decisions is not subject to public deliberation, regulatory review, or democratic input.

The absence of OpenAI and xAI from the Glasswing coalition raises a specific sub-question: if Anthropic is making decisions about who benefits from this capability through the coalition, and two of the most resourced competitors in the field are not part of that coalition, then who is not benefiting from the vulnerability-patching work Glasswing is doing? Are there categories of widely deployed software that Glasswing's coalition members are not focused on? Are there segments of the user population whose software dependencies fall outside the priorities of the twelve named partners?

These questions do not have public answers yet. What they signal is that the governance structure around the most capable AI models is currently company-specific rather than industry-wide or publicly accountable, and that the decisions made in the next twelve months about access, deployment scope, and coalition composition will have real consequences for the security posture of software systems that businesses and individuals have no control over.

Staying informed about how those decisions are made is part of operating a modern business, not in the sense of following AI news for its own sake, but in the sense that the software infrastructure every business depends on is increasingly shaped by decisions made in a small number of research labs by people whose incentives and constraints are not always aligned with the businesses and users who depend on that infrastructure.

The Mythos disclosure is the clearest signal yet that the capability frontier and the access frontier are not the same thing, that the gap between them is significant, and that the decisions about how that gap is managed over the next twelve months will matter. Completing the defensive basics now, before the lag closes, is the most concrete action available to any business owner who wants to be on the right side of that timeline.

Do it with an expert
You can build this yourself, or have it set up right the first time.

That is exactly what we do at AI DOERS. Book a private 30-minute call with Madhuranjan Kumar and we will map the fastest path to it for your specific business.

Book your call →
Madhuranjan Kumar

Madhuranjan Kumar

Founder, AI DOERS · Performance Marketing

Madhuranjan Kumar brings 20 years of performance-marketing experience and has managed over $200 million in Facebook ad spend for brands across the United States and beyond. His expertise spans the full modern marketing stack: Meta, Google Ads, TikTok, email automation, CRM, and the websites that hold it together. At AI DOERS he turns that track record into lead-generation systems for businesses across every industry.

← Back to all insights
Claude Mythos: The Model Anthropic Says It Will Not Release | AI Doers